Ransomware Surge Led by Lockbit and Conti Offshoots
NCC Group counts 198 successful ransomware campaigns in July 2023, up 47 percent from June, with Lockbit and two Conti-born groups driving most of the damage.

Key points
- Lockbit led 62 ransomware attacks in July 2023, ten more than June.
- Hiveleaks and BlackBasta, both Conti offshoots, rose 440 percent and 50 percent respectively since June.
- July's 198 successful campaigns mark a 47 percent increase over June, though still below the spring peak of nearly 300.
Lockbit ran 62 attacks in July 2023. That's ten more than it managed in June, and more than twice the combined total of the next two busiest groups. The numbers come from NCC Group researchers who monitor ransomware leak sites and scrape victim data as it appears.
Hiveleaks placed second with 27 attacks, BlackBasta third with 24. Both are Conti offshoots: Hiveleaks operated as a Conti affiliate, BlackBasta as a replacement strain spun off from the same criminal infrastructure. Their month-on-month growth tells the real story. Hiveleaks was up 440 percent since June; BlackBasta up 50 percent.
NCC Group counted 198 successful ransomware campaigns in July, a 47 percent jump from June. Sharp as that climb is, it still falls short of spring's high-water mark, when nearly 300 campaigns landed in both March and April.
How did the hackers get in?
The structural collapse of Conti is the likeliest explanation. In May, the U.S. Government offered up to $15 million for information on Conti, then the leading ransomware operation worldwide. NCC Group's authors concluded the resulting disruption pushed Conti's members to reorganise, and that Hiveleaks and BlackBasta are the direct products of that split. "It is likely that the threat actors were undergoing structural changes," the report said, "and have begun settling into their new modes of operating, resulting in their total compromises increasing in conjunction."
Conti's fingerprints haven't disappeared; they've just changed hands. We first covered the group's wider affiliate network in our 28 May story on Operation Saffron, which documented how French and Dutch police dismantled a VPN service that routed traffic for Conti and LockBit affiliates alike. That context matters here: when enforcement cuts off shared infrastructure, the crews don't quit. They rebrand and rebuild faster than investigators can follow.
NCC Group's authors noted it "would not be surprising" to see these figures rise further into August. That's a reasonable call. Once Conti's talent scatters into stable successor brands, the attack volume tends to plateau at a new, higher baseline rather than fade.
Should you worry?
If your organisation hasn't mapped its exposure to RaaS groups, this month's figures are an argument to start. Lockbit 3.0 in particular runs a mature affiliate programme: it doesn't need one sophisticated actor; it needs many competent ones. The breadth of July's 62 attacks reflects that model working exactly as designed.



